Skip to main content
Glama
72,300 servers. Updated

Matching MCP tools:

Matching MCP Connectors:

"OWASP" matching MCP servers:

  • A
    license
    A
    quality
    D
    maintenance
    MCP server that scans Salesforce Agentforce metadata for security vulnerabilities using 61+ SAST rules, integrating into AI coding workflows to guard against OWASP LLM top 10 risks.
    16
    34
    Cryptographic Autonomy 1.0 (Combined Work Exception)
  • A
    license
    A
    quality
    A
    maintenance
    Security scanning for MCP servers from the inside out. Provides runtime inspection, AST-based static analysis, config audit, dependency analysis, and OWASP MCP Top 10 compliance in a single MCP server.
    55
    21
    5
    MIT
  • F
    license
    A
    quality
    C
    maintenance
    Enterprise-grade zero-dependency security shield and runtime governance engine for MCP servers, providing OWASP MCP Top 10 audits, cryptographic tool call signing, AIBOM generation, and inline parameter firewall protection.
    3
  • A
    license
    -
    quality
    D
    maintenance
    Provides real-time OWASP ASVS security guidance and vulnerability scanning for AI coding agents. Enables proactive security during code generation by checking security requirements, scanning code for vulnerabilities, and suggesting secure code fixes.
    3
    MIT
  • F
    license
    -
    quality
    B
    maintenance
    A Model Context Protocol server for automated security vulnerability assessment, combining OWASP Dependency-Check dependency scanning with custom code vulnerability detection, and generating detailed HTML and JSON reports.
  • F
    license
    -
    quality
    C
    maintenance
    Enables local security scanning and compliance gap analysis for code and text, detecting secrets, PII, and OWASP vulnerabilities, and assessing readiness across major frameworks like NCA, ISO 27001, NIST CSF, and SOC 2.
  • A
    license
    A
    quality
    C
    maintenance
    Cross-repository code knowledge graph MCP server for Java, Kotlin, JavaScript, and TypeScript. Indexes source code into embedded KuzuDB via tree-sitter and exposes 30+ tools for call-flow tracing, multi-hop taint analysis (OWASP/CWE/PCI/STIG), entry-point reachability filtering, performance hotspot detection, and license compliance — without reading source files. 95% fewer tokens vs source-read
    33
    1
    MIT